Skip to content

Conversation

@dannyweldon
Copy link
Contributor

@dannyweldon
Copy link
Contributor Author

dannyweldon commented Jan 8, 2025

Some notes to consider before merging:

I put these at the end of the scheme list but you may want to put them higher up in the list.
These schemes are only really used by connect-src so adding them to every directive may create too much unnecessary clutter. If you search for WebSocket on this page, it only comes up against connect-src, but I could be wrong:

https://content-security-policy.com/

Without this commit, it is possible to work around this just by putting "ws:" or "wss:" directly in the edit field.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant